VendorsTRENDnettew-651br_firmwareall versions
Vulnerabilities

TRENDnet TEW-651BR Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2015-1187
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.
Published 2017-09-21 · Analyzed
10.0KEV1 PoCEPSS 0.829
CVE-2019-11399
An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. OS command injection occurs through the get_set.ccp lanHostCfg_HostName_1.1.1.0.0 parameter.
Published 2019-12-18 · Modified
10.0EPSS 0.030
CVE-2019-11400
An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. A buffer overflow occurs through the get_set.ccp ccp_act parameter.
Published 2019-12-18 · Modified
9.8EPSS 0.166
CVE-2024-51187
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the firewallRule_Name_1.1.1.0.0 parameter on the /firewall_setting.htm page.
Published 2024-11-11 · Analyzed
4.8EPSS 0.004
CVE-2024-51188
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the vsRule_VirtualServerName_1.1.10.0.0 parameter on the /virtual_server.htm page.
Published 2024-11-11 · Analyzed
4.8EPSS 0.004
CVE-2024-51189
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the macList_Name_1.1.1.0.0 parameter on the /filters.htm page.
Published 2024-11-11 · Analyzed
4.8EPSS 0.004
CVE-2024-51190
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the ptRule_ApplicationName_1.1.6.0.0 parameter on the /special_ap.htm page.
Published 2024-11-11 · Analyzed
4.8EPSS 0.004